Bump pytest from 8.4.2 to 9.0.3#3110
Conversation
There was a problem hiding this comment.
LGTM — standard Dependabot dev-dependency bump of pytest 8.4.2 → 9.0.3 in uv.lock only.
What was reviewed:
- Verified the diff touches only the
pytestentry inuv.lock; sdist/wheel URLs and hashes follow the normal PyPI pattern and the dependency list is unchanged. - Checked
pyproject.toml— the existingpytest>=8.4.0constraint already permits 9.x, so no manifest edit was required and no floor was raised. - Noted this is a major-version bump of the test framework, but it is dev-only: any behavioral breakage (e.g. pytest 9 changes interacting with
filterwarnings = ["error"]) would surface directly in CI's full 3.10–3.14 matrix rather than in shipped code.
Extended reasoning...
Overview
This PR is a Dependabot-generated bump of the pytest dev dependency from 8.4.2 to 9.0.3, touching only uv.lock. The lockfile change is the standard shape for a single-package update: version, sdist, and wheel entries replaced with new PyPI URLs, sha256 hashes, and upload timestamps; pytest's own dependency list (colorama, exceptiongroup, iniconfig, etc.) is unchanged.
Security risks
None specific to this repo's code. The update actually pulls in an upstream security fix (CVE-2025-71176, insecure temporary directory use in pytest). The artifact URLs point at files.pythonhosted.org with pinned hashes, so there is no supply-chain concern beyond trusting PyPI itself, which is the status quo.
Level of scrutiny
Low. pytest is a development-only dependency (dependency-type: direct:development per Dependabot metadata) — it never ships in the mcp wheel and cannot affect runtime users. The one notable aspect is that 8 → 9 is a major version bump of the test framework, which could break test collection or warning behavior (the repo runs with filterwarnings = ["error"]). However, that failure mode is fully gated: CI runs the complete suite with 100% coverage enforcement across Python 3.10–3.14 on Ubuntu and Windows, so any incompatibility fails visibly in CI rather than silently. The pyproject.toml constraint pytest>=8.4.0 already allows 9.x, so no manifest or floor change was needed, consistent with the repo's dependency policy.
Other factors
The bug hunting system found no issues, and there are no reviewer comments or prior reviews on the PR. There is nothing here for a human to weigh in on beyond what CI already validates mechanically.
Bumps [pytest](https://github.com/pytest-dev/pytest) from 8.4.2 to 9.0.3. - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst) - [Commits](pytest-dev/pytest@8.4.2...9.0.3) --- updated-dependencies: - dependency-name: pytest dependency-version: 9.0.3 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
071eb31 to
4bba7a2
Compare
There was a problem hiding this comment.
LGTM — routine Dependabot lockfile-only bump of pytest 8.4.2 → 9.0.3, a test-only dependency.
What was reviewed:
- The diff touches only the
uv.lockentry for pytest (version, sdist/wheel URLs and hashes); no other packages or dependency entries changed. - Confirmed the bump is compatible with the
pytest>=8.4.0constraint inpyproject.toml, so no constraint edit was needed. - Since this crosses a major version (8 → 9) and the repo runs with
filterwarnings = ["error"], verified locally that pytest 9.0.3 resolves from the lock, all pytest plugins load, and a test module passes under it.
Extended reasoning...
Overview
This is a Dependabot PR that bumps pytest from 8.4.2 to 9.0.3 in uv.lock only. No source code, configuration, or dependency constraints change — pyproject.toml already allows pytest>=8.4.0, so the lockfile update is self-contained. pytest is a dev/test-only dependency and is not part of the published package's runtime dependencies.
Security risks
None. The change swaps the locked pytest sdist/wheel for the official 9.0.3 artifacts from PyPI with pinned SHA-256 hashes, so supply-chain integrity is preserved by the hash pins. The new release also fixes CVE-2025-71176 (insecure temporary directory) in pytest itself, which is a small net security improvement for the development environment.
Level of scrutiny
Low. This is a mechanical lockfile bump of a test-only dependency. The one point deserving attention is that it crosses a major version boundary (pytest 8 → 9), which could break the test suite (the repo treats warnings as errors). I verified locally that pytest 9.0.3 is active under uv run --frozen, that all configured pytest plugins (anyio, xdist, flakefinder, examples, pretty, inline-snapshot) load without error, and that a representative test module (tests/client/test_client.py, 46 tests) passes. CI additionally runs the full matrix (3.10–3.14 × ubuntu/windows × locked/lowest-direct) with 100% coverage enforcement, so any remaining incompatibility would be caught before merge.
Other factors
The PR timeline has no prior reviews or comments to address. The bug hunting system found no issues. The change follows the repository's standard Dependabot flow (labels dependencies, python:uv), and lockfile bumps of dev dependencies are exactly the class of change that does not need human design judgment.
Bumps pytest from 8.4.2 to 9.0.3.
Release notes
Sourced from pytest's releases.
... (truncated)
Commits
a7d58d7Prepare release version 9.0.3089d981Merge pull request #14366 from bluetech/revert-14193-backport8127eafRevert "Fix: assertrepr_compare respects dict insertion order (#14050) (#14193)"99a7e60Merge pull request #14363 from pytest-dev/patchback/backports/9.0.x/95d8423bd...ddee02aMerge pull request #14343 from bluetech/cve-2025-71176-simple74eac69doc: Update training info (#14298) (#14301)f92dee7Merge pull request #14267 from pytest-dev/patchback/backports/9.0.x/d6fa26c62...7ee58acMerge pull request #12378 from Pierre-Sassoulas/fix-implicit-str-concat-and-d...37da870Merge pull request #14259 from mitre88/patch-4 (#14268)c34bfa3Add explanation for string context diffs (#14257) (#14266)